s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.gorilla

📛 Threat Title

Malware family: Gorilla

Category: Gorilla First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.gorilla`. Printable name: Gorilla.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.gorilla VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gorilla

IOC database

Type
domain
Value
elf.gorilla
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.gorilla

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.gorilla

References (1)

Remediations (10)

  • web:base4sec.com

    Mitigation focuses on isolating infected systems to prevent further spread, followed by a complete removal of the malware from the botnet. This process typically involves: Network segmentation: Limit the movement of malicious traffic by isolating infected devices from the rest of the network.

  • web:blog.netmanageit.com

    The malware uses raw TCP sockets and a custom XTEA-like cipher for C2 communication, implements anti-debugging and anti-analysis checks, and authenticates to its C2 server using a SHA-256-based token. Attack commands are encoded, hashed, and processed using a Mirai-style attack_parse function.

  • web:cyberflorida.org

    Gorilla Bot is an advanced malware strain first detected in early 2025, specializing in automated credential stuffing, web scraping, and distributed denial-of-service (DDoS) attacks.

  • web:github.com

    Gorilla is an evolving Android malware that focuses on SMS interception and persistent C2 communication while avoiding permission restrictions and battery optimizations. Though still in development, it already employs stealthy techniques and may introduce phishing or new persistence mechanisms in future versions. The full report is available .

  • web:gsmaragd.github.io

    We com- bine attack data obtained from our milker with network tele- scope data, netflow records, and Gorilla malware binaries to provide the first in-depth characterization of the Gorilla Bot- net architecture, the modern DDoS-for-Hire economy, and DDoS attack economics.

  • web:malpedia.caad.fkie.fraunhofer.de

    A DDoS botnet, based on Mirai. 2024-10-10 ⋅ NCSC Switzerland ⋅ NCSC Switzerland Brief technical analysis of the " Gorilla " botnet Gorilla Gorilla

  • web:repository.tudelft.nl

    This thesis conducts a detailed analysis of the Gorilla botnet, focusing on its communication patterns, infection strategies, and attack behaviors. By executing Gorilla's malware samples in a controlled environment, the study captures insights into its command-and-control (C2) communication and attack strategies.

  • web:repository.tudelft.nl

    This thesis conducts a detailed analysis of the Gorilla botnet, focusing on its communication patterns, infection strategies, and attack behaviors. By executing Gorilla's malware samples in a controlled environment, the study captures insights into its command-and-control (C2) communication and attack strategies.

  • web:thehackernews.com

    Cybersecurity researchers have discovered a new botnet malware family called Gorilla (aka GorillaBot) that draws its inspiration from the leaked Mirai botnet source code. Cybersecurity firm NSFOCUS, which identified the activity last month, said the botnet "issued over 300,000 attack commands, with ...

  • web:www.ncsc.admin.ch

    In addition, the Telegram channel of " Gorilla Services" was shut down by means of a complaint sent to Telegram. The technical report sheds light on the infrastructure used by the " Gorilla " botnet and the malware used by the attackers. The malware has code similarities to the "Mirai" and infects devices with a Linux/Unix operating system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.